
GIAC Enterprise Incident Responder
Domain 4Objective 1
Linux Essentials GEIR Practice Questions (Page 3)
Part of the Linux Forensics domain, which makes up ~16% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~11–19 in this domain), expect 6–10 from this objective — we provide 29 practice questions to prepare you well beyond it. (estimate)
29questions here
6free pages
10concepts
Questions 11–15
- 11
An incident responder needs to examine runtime system information, such as kernel parameters, memory details, and process status, without reading from disk. Which directory provides a virtual, kernel-generated view of the system?
Select an answer first - 12
A forensic investigator needs to preserve the permissions and ownership of a directory tree while copying it to an external drive for analysis. The investigator also needs to ensure that the copy does not follow symbolic links. Which command should be used?
Select an answer first - 13
An analyst needs to view the most recent kernel ring buffer messages, such as hardware detection and driver messages, on a Linux system. Which command displays this information?
Select an answer first - 14
An investigator wants to find all lines in a log file that contain the word 'error' (case-insensitive) and also display the line numbers. Which command accomplishes this?
Select an answer first - 15
While investigating a suspicious process, an analyst needs to display all currently running processes with their full command lines, including processes from all users. Which command provides this information?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GEIR” is a trademark of its owner, used for identification only.